CVE-2026-0969

The serialize function used to compile MDX in next-mdx-remote is vulnerable to arbitrary code execution due to insufficient sanitization of MDX content. This vulnerability, CVE-2026-0969, is fixed in next-mdx-remote 6.0.0.
Configurations

No configuration.

History

15 Apr 2026, 00:35

Type Values Removed Values Added
Summary
  • (es) La función serialize utilizada para compilar MDX en next-mdx-remote es vulnerable a ejecución de código arbitrario debido a la sanitización insuficiente del contenido MDX. Esta vulnerabilidad, CVE-2026-0969, está corregida en next-mdx-remote 6.0.0.

12 Feb 2026, 15:16

Type Values Removed Values Added
Summary (en) The serialize function used to compile MDX in next-mdx-remote is vulnerable to arbitrary code execution due to insufficient sanitization of MDX content. (en) The serialize function used to compile MDX in next-mdx-remote is vulnerable to arbitrary code execution due to insufficient sanitization of MDX content. This vulnerability, CVE-2026-0969, is fixed in next-mdx-remote 6.0.0.

12 Feb 2026, 03:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-12 03:15

Updated : 2026-06-17 10:11


NVD link : CVE-2026-0969

Mitre link : CVE-2026-0969

CVE.ORG link : CVE-2026-0969


JSON object : View

Products Affected

No product.

CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')